Published: · Region: Global · Category: cyber

Warlock Ransomware Uses Unpatched SharePoint to Hit Utility, Telecom, Government and University Networks

A ransomware group tracked as Warlock has been exploiting old vulnerabilities in Microsoft SharePoint to breach a water utility, a telecom operator, a government body and a university, disabling security tools on 40 hosts in about two hours before pushing malware to 33 machines, according to new technical reporting.

Recent attacks by a group known as Warlock show how unpatched collaboration software can open the door to serious ransomware incidents across critical and public‑sector networks.

According to a detailed technical report, Warlock has used known but unpatched flaws in Microsoft SharePoint over the past two months to compromise at least four organizations: a water utility, a telecommunications company, a government agency, and a university. SharePoint is widely used for internal document sharing and often sits close to core identity and file‑storage systems.

In one case described by researchers, the attackers moved quickly once they were inside. They disabled security tools on 40 hosts in roughly two hours, then abused the Windows SYSVOL directory—which distributes scripts and policies across domain‑joined machines—to push ransomware to 33 systems. Using a built‑in Windows mechanism in this way made the intrusion harder to spot and helped the malware spread.

For the water utility, the attack raises worries that extend beyond data loss. The report did not state whether control systems for pumps or treatment plants were affected, but significant IT outages in such environments can slow billing and monitoring and, if they spill over, could touch systems that oversee physical processes. Telecom and university victims face their own risks, from service disruption to exposure of personal or research data.

Government agencies often rely on aging software and tight budgets, yet hold large volumes of sensitive information. When a group like Warlock turns a vulnerable SharePoint server into an initial foothold, the result can be prolonged disruption to public services and expensive recovery efforts.

The technical picture is stark because it involves no new, unknown exploit. Warlock is leveraging security holes that organizations have had the chance to fix. Leaving SharePoint instances unpatched or poorly isolated effectively hands attackers an easy entry point.

For defenders, these incidents underline that platforms used for collaboration can provide broad access if compromised, and that attackers are comfortable hijacking legitimate tools such as SYSVOL to distribute malicious code.

Signals to watch include whether any of the affected organizations publicly disclose incidents or ransom payments, how national cybersecurity agencies update their guidance on securing SharePoint, and whether similar attack chains crop up in sectors such as healthcare or energy. Patch uptake and network segmentation around collaboration platforms will show whether these cases prompt concrete changes in defense.

Sources